World2022decoding virus: what is known so far?
The pattern of renaming is the following: [victimID].world2022decoding. In the course of encryption, a file named, for instance, âreport.docxâ will be altered to âreport.docx.[9222911A].world2022decodingâ.
In every folder that contains the encoded files, a WE CAN RECOVER YOUR DATA.MHT file will be found. It is a ransom money note. Therein you can find information on the ways of contacting the racketeers and some other remarks. The ransom note most probably contains a description of how to purchase the decryption tool from the ransomware developers. That is it.
| Name | World2022decoding Virus |
| Extension | .world2022decoding |
| Ransomware note | WE CAN RECOVER YOUR DATA.MHT |
| Detection1 | Win32/TrojanDownloader.FlyStudio.AY, Trojan:Win32/Vundo!AU, Trojan:Win32/Redline.MKW!MTB |
| Symptoms | Your files (photos, videos, documents) get a .world2022decoding extension and you canât open them. |
| Fix Tool | See If Your System Has Been Affected by World2022decoding virus |
The WE CAN RECOVER YOUR DATA.MHT file coming in package with the World2022decoding malware provides the following dispiriting information:
YOUR FILES ARE ENCRYPTED Your files, documents, photos, databases and other important files are encrypted. You are not able to decrypt it by yourself! The only method of recovering files is to purchase an unique private key. Only we can give you this key and only we can recover your files. To be sure we have the decryptor and it works you can send an email: and decrypt one file for free. But this file should be of not valuable! Do you really want to restore your files? Write to email: Reserved email: Your personal ID: - Attention! Do not rename encrypted files. Do not try to decrypt your data using third party software, it may cause permanent data loss. Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.
In the image below, you can see what a folder with files encrypted by the World2022decoding looks like. Each filename has the â.world2022decodingâ extension appended to it.
How did my computer get infected with World2022decoding ransomware?
There are currently three most exploited methods for tamperers to have ransomware working in your digital environment. These are email spam, Trojan infiltration and peer-to-peer file transfer.
If you open your inbox and see emails that look like familiar notifications from utility services providers, postal agencies like FedEx, web-access providers, and whatnot, but whose sender is strange to you, be wary of opening those letters. They are most likely to have a malware item enclosed in them. Thus it is even riskier to download any attachments that come with letters like these.
Another thing the hackers might try is a Trojan horse model2. A Trojan is an object that infiltrates into your computer disguised as something different. For example, you download an installer of some program you need or an update for some program. However, what is unpacked turns out to be a harmful program that encrypts your data. As the update file can have any name and any icon, youâd better be sure that you can trust the resource of the things youâre downloading. The best way is to use the software developersâ official websites.
As for the peer-to-peer networks like torrent trackers or eMule, the danger is that they are even more trust-based than the rest of the Web. You can never know what you download until you get it. So youâd better be using trustworthy resources. Also, it is a good idea to scan the directory containing the downloaded items with the antivirus as soon as the downloading is complete.